lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <BAY112-W363A32D7BEA03CF26FB32A83020@phx.gbl>
Date: Fri, 14 Aug 2009 11:38:17 +0100
From: Shine Shadow <ss_contacts@...mail.com>
To: <bugtraq@...urityfocus.com>
Cc: cve@...re.org, full-disclosure@...ts.grok.org.uk
Subject: ICQ 6.5 HTML-injection vulnerability


ShineShadow Security Report  14082009-08

TITLE 

ICQ 6.5 HTML-injection vulnerability

BACKGROUND 

With more than 700 million instant messages sent and received every day, ICQ has been known to the online community as a messaging service. Today, a little more than a decade after the first ICQ instant messaging service was launched it has become much more than just that. 
ICQ is a personal communication tool that allows users to meet and interact through instant messaging services such as text, voice, video and VoIP as well as various entertainment and community products. 
 
Source: http://www.icq.com
 
VULNERABLE PRODUCTS 

ICQ 6.5 build 1042 (latest build)
Previous versions and localized distributions may also be affected

DETAILS 

HTML-injection vulnerability exists in official ICQ client software. Incoming message window in the vulnerable ICQ client has a web browser nature. An attacker can try to exploit the vulnerability by sending specially crafted message to the remote ICQ client. The malicious message can contain text data which will be interpreted and displayed in the incoming message window as a HTML code. Potentially an arbitrary HTML code could be injected.
There are two impacts of the vulnerability has been detected:
1.  Information disclosure
For example, an attacker can inject <IMG> tag that could lead information disclosure (such as remote client’s IP address, browser version, OS version, etc.)
2.  Spoofing
An attacker can spoof ICQ client software’s system messages, interface elements (buttons, links) in the message window, etc. For example, it could be used for forcing of the ICQ users to click on attacker’s malicious link.
Maybe other impacts are possible.
 
EXPLOITATION 

Remote attacker can exploit this vulnerability using any instant messenger software with OSCAR (ICQ) protocol support by sending specially crafted message.
Example of exploit message:
file://1"></a>[HTML CODE]
Notice that internal ICQ antispam engine will blocked some text/html data if attacker’s ICQ UIN not in user’s ICQ contact list.

DISCLOSURE POLICY
 
The “Full disclosure” policy has been applied. Vendor has not been contacted.

CREDITS 

Maxim A. Kulakov (aka ShineShadow)
ss_contacts@...mail.com
 
_________________________________________________________________
Celebrate a decade of Messenger with free winks, emoticons, display pics, and more.
http://clk.atdmt.com/UKM/go/157562755/direct/01/
Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ